Builder
Make a launch decision.
See the highest-priority risks in plain language, what the scan could not prove, and what to do next.

Open registration · Release assurance for AI-built apps
Turn an authorized target, retained evidence, and a fresh retest into one reviewable assurance record.
Passive public-surface check · No account required · Full platform open for registration
Live URL scan · passive and read-only
Look for exposed secrets, missing browser protections, risky data-layer signals, and HTTPS issues. Results in seconds. No signup.
What the Lite Check covers and cannot proveRelease assurance for AI-built apps
Move from an authorized target to a reviewable assurance record without blurring detection, proof, and retest outcomes.
01 / Target
Name the target, scope, and permissions before any check begins. Coverage starts with an explicit boundary.
02 / Scan
Deterministic scanners and AI-assisted review remain separate coverage layers, never a universal guarantee.
03 / Evidence State
Results remain detected until independent verification exists. Retest-confirmed and inconclusive outcomes stay distinct.
04 / Fix Proposal
A proposal can explain and stage a fix. PR execution remains blocked until a server-generated patch is bound to exact approval.
05 / Retest
Complete deterministic coverage can validate a clean retest. Engine-only absence remains inconclusive.
06 / Assurance Report
Coverage, findings, evidence states, retest outcomes, and limitations assemble into one reviewable report.
Scope stated · limitations retainedThe full product keeps scope, coverage, evidence, fixes, and retests in one release record. Missing proof stays visible instead of becoming a silent pass.
Assurance state
Review required
Two detected candidates still need independent evidence before this sample release can be treated as verified.
Illustrative evidence ledger
Counts show product states, not production performance.
Vibe Security 50 registry
Machine checks and human evidence stay separate by design.
Builder
See the highest-priority risks in plain language, what the scan could not prove, and what to do next.
Agency
Share an immutable executive or developer report without exposing repository coordinates or technical evidence.
Small team
Use roles, audit history, schedules, notifications, GitHub checks, and approval-gated agent actions.
These focused tools run in your browser and explain their limits. No account and no upload required.
Compatible MCP clients can read findings, check launch readiness, start scans, and create reports. Mutating actions require explicit approval on the controlling terminal and fail closed when no terminal is available.
It is a review record that states which authorized checks ran, what they covered, the evidence behind each result, and what a retest established before a release ships.
The passive Lite Check and five browser-local tools are public. The full release-assurance platform is live with open registration and remains in active development; subscribe for product updates.
Only what the retained evidence supports. New scans distinguish detected candidates, independently verified findings, validated fixes, inconclusive retests, and checks that were limited or not applicable.
Not yet. LyraShield creates approval-gated fix proposals, but PR execution stays blocked until the patch is generated server-side and bound to the exact approval.
No. SCA, secret scanning, URL checks, and repository review are coverage layers inside a wider assurance workflow. Specialist tools may still provide deeper coverage in their category.
Pricing and plan boundaries will be announced as the open beta matures.
Stay in the loop on new evidence states, scan depth, and ways to share an honest assurance record.